Техническая информация
- '<SYSTEM32>\regini.exe' "%TEMP%\write.dll"
- '%WINDIR%\regedit.exe' /s "%TEMP%\update.dll"
- '<SYSTEM32>\regini.exe' "%TEMP%\readonly.dll"
- '<SYSTEM32>\cacls.exe' "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk" /c /t /g everyone:f
- '<SYSTEM32>\cacls.exe' "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk" /c /t /g everyone:r
- '<SYSTEM32>\cacls.exe' "<Имя диска съемного носителя>:\desktop\desk\Internet Explorer.lnk" /c /t /g everyone:f
- %TEMP%\update.dll
- %TEMP%\readonly.dll
- %TEMP%\write.dll
- <Текущая директория>\input
- <SYSTEM32>\msorc32l.dll
- %TEMP%\readonly.dll
- <Текущая директория>\input
- %TEMP%\update.dll
- %TEMP%\write.dll
- ClassName: 'MS_WINHELP' WindowName: '(null)'
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'